Broken Access Control Vulnerability in HCL DominoIQ
CVE-2026-21836
6.5MEDIUM
What is CVE-2026-21836?
The HCL DominoIQ features an access control vulnerability that can lead to unauthorized data exposure. When certain conditions are met, the intended document-level access restrictions may not be enforced, allowing authenticated attackers to retrieve sensitive information from AI queries. This flaw underscores the importance of verifying access permissions in AI-integrated applications to prevent inadvertent data leaks.
Affected Version(s)
DominoIQ 14.5.1
